Skip to content
Ubiquiti UniFi, UniFi OS console

UDM Pro guest portal setup

The UDM Pro runs UniFi OS, and UniFi OS changes three things a portal integration depends on: the login endpoint, a path prefix in front of every Network call, and a CSRF token that has to come back on each request. The integration handles all three; your job is the hotspot settings and reachability.

How do I set up a guest portal on a UDM Pro?
In the Network application enable the hotspot portal on your guest SSID, choose External Portal Server, enter www.voqadowifi.com, and add www.voqadowifi.com and voqadowifi.com to Pre-Authorization Access. Create a local admin without two factor, make the console reachable over HTTPS, then save its address, the site (usually default) and that login in the dashboard.

At a glance

Runs
UniFi OS
Address for the dashboard
HTTPS on 443, no port
Login the integration uses
/api/auth/login
Network API prefix
/proxy/network
Usual site id
default
Guest lands on
https://www.voqadowifi.com/guest/s/default/

Checked against the VoqadoWiFi integration code on 7 October 2026. Controller menu labels move between firmware releases; the setting names above are the ones the setup wizard prints.

Step by step

  1. Enable the hotspot portal on the guest SSID
    In Settings, WiFi, edit the guest SSID and turn on the hotspot or guest portal. Keep the SSID open; the portal is the gate.
  2. Point the external portal server at VoqadoWiFi
    In the hotspot settings choose External Portal Server and enter the host www.voqadowifi.com. UniFi always sends guests to the fixed path /guest/s/<site>/ on that host, which is how VoqadoWiFi knows which venue they are at. If your Network version asks for an IP address, switch on Redirect using hostname and enter the host there instead.
  3. Add the pre-authorization entries and leave HTTPS redirection off
    Add www.voqadowifi.com and voqadowifi.com to Pre-Authorization Access. If your version shows an HTTPS Redirection toggle, leave it off: intercepting HTTPS is what produces certificate warnings on guest phones.
  4. Create a local admin for the integration
    Under Admins and Users add an account restricted to local access, with access to the Network application and no two factor prompt. A ui.com cloud account cannot log in to the controller API, and a two factor challenge fails every automated login.
  5. Make the console reachable from the internet
    The authorization call comes from VoqadoWiFi’s servers. Either forward TCP 443 to the console behind a DDNS hostname, or run an outbound tunnel to it, which also works behind carrier grade NAT.
  6. Save the console in the dashboard and test the connection
    Choose Ubiquiti UniFi as the network vendor, enter the console’s https:// address with no port, the local admin, and leave Console Type on Auto-detect. Test Connection lists every site as id and name; click yours to fill the UniFi Site field.

What breaks on this controller

A proxy or tunnel strips the CSRF header

UniFi OS rejects state changing calls without a CSRF token, with 401 or 403. Some reverse proxies drop the x-csrf-token header. The integration falls back to the token inside the TOKEN session cookie, so a tunnelled UDM Pro still authorizes guests.

Port 8443 in the address

8443 belongs to the older self hosted controller. A UniFi OS console answers on 443. With Auto-detect, the integration probes the root of the address: a 200 means UniFi OS, a redirect to /manage means the older controller.

A ui.com account in the dashboard

Cloud accounts and accounts with two factor cannot complete an API login. Portal Health shows auth with “login rejected”. Create a local admin as in step 4.

Two venues, two consoles, one site name

Every single site console calls its site default, so two shops on separate UDMs both send guests to /guest/s/default/. Add each venue’s access point MACs to its location in the dashboard and VoqadoWiFi matches the guest to the right venue from the ap parameter.

What the integration does on every guest

It logs in at /api/auth/login on the console, reads the CSRF token from the response header or, failing that, from the TOKEN cookie, then posts authorize-guest for the guest’s MAC to /proxy/network/api/s/<site>/cmd/stamgr with a session length in minutes and the access point MAC.

Each attempt has an 8 second limit and there are two attempts. A rejected login is not retried, because a wrong password will not fix itself. A stale session is retried with a fresh login.

Questions

Does this work on the UDM SE, UDM and UDR too?
Yes. They run UniFi OS like the UDM Pro, so the login endpoint, the /proxy/network prefix and the CSRF handling are the same.
Can I use unifi.ui.com remote access as the controller address?
No. Remote access through ui.com is for people. The authorization call needs a direct HTTPS address for the console, through a forwarded port or a tunnel.
Do I have to type the site name?
You can, but Test Connection lists every site the account can see as id and display name, and clicking one fills the field with the exact id.
Does guest isolation need to change?
No, leave it on. Check from a guest device that the console’s own management address is unreachable; on a gateway that is also the controller, that is worth verifying once.

Deeper reading

Longer articles from the blog that cover this controller. Where an article and this page disagree, this page is the one checked against the current integration.

Keep reading

UniFi setup hubUniFi authorize returns 403UniFi Cloud Gateway setupWalled garden domains

Sources: lib/unifi/api.ts, app/guest/s/[site]/route.ts and docs/unifi-setup-guide.md, read on the date above. Ubiquiti and UniFi are trademarks of Ubiquiti Inc. VoqadoWiFi is not affiliated with or endorsed by either vendor.

Run your UniFi portal free

One location and 25 guest logins a month on the Starter plan, no card. The dashboard prints the finished portal URL for this controller.

Free forever plan. No credit card and no sales call.